AWS X-Ray

eventNameDescriptionSampleRule
anyCatch-all entry for AWS X-Ray rules that match the service but not a specific eventName.NN
BatchGetTracesYou cannot find traces through this API if Transaction Search is enabled since trace is not indexed in X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelTraceRetrievalCancels an ongoing trace retrieval job initiated by StartTraceRetrieval using the provided RetrievalToken. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateGroupCreates a group resource with a name and a filter expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateSamplingRuleCreates a rule to control sampling behavior for instrumented applications. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteGroupDeletes a group resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourcePolicyDeletes a resource policy from the target Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSamplingRuleDeletes a sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetEncryptionConfigRetrieves the current encryption configuration for X-Ray data.YN
GetGroupRetrieves group resource details. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetGroupsRetrieves all active group details. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetIndexingRulesRetrieves all indexing rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetInsightRetrieves the summary information of an insight. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetInsightEventsX-Ray reevaluates insights periodically until they're resolved, and records each intermediate state as an event. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetInsightImpactGraphRetrieves a service graph structure filtered by the specified insight. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetInsightSummariesRetrieves the summaries of all insights in the specified group matching the provided filter values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetRetrievedTracesGraphRetrieves a service graph for traces based on the specified RetrievalToken from the CloudWatch log group generated by Transaction Search. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSamplingRulesRetrieves all sampling rules. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSamplingStatisticSummariesRetrieves information about recent sampling results for all sampling rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSamplingTargetsRequests a sampling quota for rules that the service is using to sample requests. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetServiceGraphRetrieves a document that describes services that process incoming requests, and downstream services that they call as a result. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTimeSeriesServiceStatisticsGet an aggregation of service statistics defined by a specific time range. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTraceGraphRetrieves a service graph for one or more specific trace IDs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTraceSegmentDestinationRetrieves the current destination of data sent to PutTraceSegments and OpenTelemetry protocol (OTLP) endpoint. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetTraceSummariesRetrieves IDs and annotations for traces available for a specified time frame using an optional filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListResourcePoliciesReturns the list of resource policies in the target Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListRetrievedTracesRetrieves a list of traces for a given RetrievalToken from the CloudWatch log group generated by Transaction Search. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsForResourceReturns a list of tags that are applied to the specified Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutEncryptionConfigUpdates the encryption configuration for X-Ray data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutResourcePolicySets the resource policy to grant one or more Amazon Web Services services and accounts permissions to access X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutTelemetryRecordsUsed by the Amazon Web Services X-Ray daemon to upload telemetry. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutTraceSegmentsUploads segment documents to Amazon Web Services X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartTraceRetrievalInitiates a trace retrieval process using the specified time range and for the given trace IDs in the Transaction Search generated CloudWatch log group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceApplies tags to an existing Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves tags from an Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateGroupUpdates a group resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateIndexingRuleModifies an indexing rule’s configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSamplingRuleModifies a sampling rule's configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTraceSegmentDestinationModifies the destination of data sent to PutTraceSegments. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS X-Ray (catch-all)

#
Service
xray

Description

Catch-all entry for AWS X-Ray rules that match the service but not a specific eventName.

BatchGetTraces

#
Service
xray

Description

You cannot find traces through this API if Transaction Search is enabled since trace is not indexed in X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelTraceRetrieval

#
Service
xray

Description

Cancels an ongoing trace retrieval job initiated by StartTraceRetrieval using the provided RetrievalToken. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateGroup

#
Service
xray

Description

Creates a group resource with a name and a filter expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateSamplingRule

#
Service
xray

Description

Creates a rule to control sampling behavior for instrumented applications. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteGroup

#
Service
xray

Description

Deletes a group resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourcePolicy

#
Service
xray

Description

Deletes a resource policy from the target Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSamplingRule

#
Service
xray

Description

Deletes a sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetEncryptionConfig

#
Service
xray

Description

Retrieves the current encryption configuration for X-Ray data.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: xray:GetEncryptionConfig",
  "eventCategory": "Management",
  "eventID": "26e074ac-009c-42bc-b36f-29852e335d66",
  "eventName": "GetEncryptionConfig",
  "eventSource": "xray.amazonaws.com",
  "eventTime": "2021-04-13T11:35:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "03fc490a-f91e-415a-a451-9b4860774ac8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

GetGroup

#
Service
xray

Description

Retrieves group resource details. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetGroups

#
Service
xray

Description

Retrieves all active group details. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3f455ef1-af53-4921-843d-77d1b582bd9c",
  "eventSource": "xray.amazonaws.com",
  "eventName": "GetGroups",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "89860412-832e-470e-98da-3993f41bf2fe",
  "userAgent": "aws-sdk-go/1.54.20 (go1.21.13; linux; amd64)",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetIndexingRules

#
Service
xray

Description

Retrieves all indexing rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetInsight

#
Service
xray

Description

Retrieves the summary information of an insight. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetInsightEvents

#
Service
xray

Description

X-Ray reevaluates insights periodically until they're resolved, and records each intermediate state as an event. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetInsightImpactGraph

#
Service
xray

Description

Retrieves a service graph structure filtered by the specified insight. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetInsightSummaries

#
Service
xray

Description

Retrieves the summaries of all insights in the specified group matching the provided filter values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetRetrievedTracesGraph

#
Service
xray

Description

Retrieves a service graph for traces based on the specified RetrievalToken from the CloudWatch log group generated by Transaction Search. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSamplingRules

#
Service
xray

Description

Retrieves all sampling rules. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d02e7321-99f9-4b32-bbb7-a8687f4e8295",
  "eventSource": "xray.amazonaws.com",
  "eventName": "GetSamplingRules",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a07d5305-82bb-4fd1-aefe-2b917083e1dd",
  "userAgent": "apigateway.amazonaws.com"
}

GetSamplingStatisticSummaries

#
Service
xray

Description

Retrieves information about recent sampling results for all sampling rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSamplingTargets

#
Service
xray

Description

Requests a sampling quota for rules that the service is using to sample requests. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetServiceGraph

#
Service
xray

Description

Retrieves a document that describes services that process incoming requests, and downstream services that they call as a result. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTimeSeriesServiceStatistics

#
Service
xray

Description

Get an aggregation of service statistics defined by a specific time range. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTraceGraph

#
Service
xray

Description

Retrieves a service graph for one or more specific trace IDs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTraceSegmentDestination

#
Service
xray

Description

Retrieves the current destination of data sent to PutTraceSegments and OpenTelemetry protocol (OTLP) endpoint. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a76920fe-49eb-4e0c-8d29-c75a3e208c57",
  "eventSource": "xray.amazonaws.com",
  "eventName": "GetTraceSegmentDestination",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "690dfe75-c00a-456e-8f23-f0d77db2d454",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetTraceSummaries

#
Service
xray

Description

Retrieves IDs and annotations for traces available for a specified time frame using an optional filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListResourcePolicies

#
Service
xray

Description

Returns the list of resource policies in the target Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListRetrievedTraces

#
Service
xray

Description

Retrieves a list of traces for a given RetrievalToken from the CloudWatch log group generated by Transaction Search. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTagsForResource

#
Service
xray

Description

Returns a list of tags that are applied to the specified Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutEncryptionConfig

#
Service
xray

Description

Updates the encryption configuration for X-Ray data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutResourcePolicy

#
Service
xray

Description

Sets the resource policy to grant one or more Amazon Web Services services and accounts permissions to access X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutTelemetryRecords

#
Service
xray

Description

Used by the Amazon Web Services X-Ray daemon to upload telemetry. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutTraceSegments

#
Service
xray

Description

Uploads segment documents to Amazon Web Services X-Ray. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartTraceRetrieval

#
Service
xray

Description

Initiates a trace retrieval process using the specified time range and for the given trace IDs in the Transaction Search generated CloudWatch log group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
xray

Description

Applies tags to an existing Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
xray

Description

Removes tags from an Amazon Web Services X-Ray group or sampling rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateGroup

#
Service
xray

Description

Updates a group resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateIndexingRule

#
Service
xray

Description

Modifies an indexing rule’s configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSamplingRule

#
Service
xray

Description

Modifies a sampling rule's configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTraceSegmentDestination

#
Service
xray

Description

Modifies the destination of data sent to PutTraceSegments. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.